AI description
Automated description summarized from trusted sources.
CVE-2026-16380 is identified as a Remote Code Execution (RCE) vulnerability affecting Mozilla Firefox, specifically versions up to 152. This flaw resides within the browser's networking component, where certain manipulations can lead to the execution of arbitrary code. The attack exploiting this vulnerability can be initiated remotely.
- Description
- Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- Source
- security@mozilla.org
- NVD status
- Undergoing Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-693
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
16